The introduction
Cloud services and deployment models
Cloud Concerns for Data Protection Authorities
1.1. Introduction
The advantages of cloud services make it attractive to an extensive range of business, public, and governmental organisations for all sizes and types of enterprises. Such organisations might lack the resources and skills to manage in-house complex and expensive internal IT platforms.
, through to larger international corporates attracted to each other for potential financial benefits.
Nonetheless, despite the complex administration and economic benefits of using the cloud, there are numerous information security and privacy protection issues, primarily when the cloud is used for processing or handling personal information. The problems result from the various business, public and governmental organisations’ apparent lack of control over and oversight of how personal information is protected and managed within each organisations’ domain.
The discussion covers problem areas that cloud customers should consider when making decisions to engage the services of a cloud service provider. A view of the fundamental data protection principles behind the obligations of data users and data controllers[1] and then provides the more common data protection issues which enterprises experience when pursuing the services of a cloud service provider. The discussion outlines some business model characteristics that cloud service providers have adopted and how these characteristics impact the protection of personal data and data privacy.
The inputs provided below should stand deliberated when enterprising customers consider or address engaging the services of a cloud service provider.
1.2. Cloud Service and Deployment Models
There are numerous categories and characteristics of the cloud.
This segment focuses on service and deployment models, considering the applicable privacy and personal data protection regulation: private and public cloud service models, incorporating SaaS, PaaS and IaaS, deployment models.
The relevant service models, private and public cloud
The private cloud stands intended for the exclusive use of private organisations. Organisational customers ought to mandate all the necessary controls to safeguard and protect the organisation’s use of personal data by the selected cloud service provider.
In contrast, public cloud models stand predestined to be shared by multiple customers with various individual needs. Hence, public cloud service providers tend to make the cloud platforms generic in design, allowing engagement and drawing as many customers as possible. As such, the level of provision and controls exercised by organisational clients of public clouds is inevitably much lower when compared to that of private cloud service providers.
As far as personal data protection is concerned, the primary distinction between the various deployment models is that in using the SaaS model, the cloud service provider also supplies and frequently operates the related software for the data users. In the SaaS model, the cloud service provider’s software may not be completely customisable to the data customers’ or users’ compliance and security requirements. In addition, it should stand noted that some SaaS cloud service providers cooperate directly with data users’ clients or customers, which renders the roles and responsibilities of each party in respect of ‘who is collecting what personal data and for ‘what purpose’ even fuzzier. The PaaS and IaaS models, in contrast, allow data users to install their software, which can stand safely assumed to be more readily compliant with a specific business, security and regulatory requirements of the data users.
1.3. Cloud Concerns for Data Protection Authorities
Cloud computing is undoubtedly a very attractive business enabler, offering such benefits as a short lead time, minimal investment and ease of use for any business initiative or operation that requires IT support. In 2012, Gartner, a market-leading IT advisory and research firm, had historically estimated that the cloud would grow from 11 billion dollars in 2012 to 244 billion dollars by 2017.
However, the cloud still has inherent risks such as the lack of control and breach of personal data possibilities. The EU had set up a ‘Working Party’ initialised by Article 29 of the old Data Protection Directive 95/46/EC (1995), which consisted of agents from each Member States Data Protection Authorities and the EU Commission and Data Protection Supervisor. Among its aims are to advise the EC and make recommendations to the EU concerning personal data protection. It considers the lack of control over and the deficiency of information about the cloud operations to be the two critical risks associated with using the cloud.[2]
South Africa’s interpretation comes via the POPI Act.[3] Many of the POPI Acts provisions are similar to those found in the now repealed EU Data Protection Directive 95/46/EC (1995),[4] and one can see where the inspiration originates. The Scope of Application of the POPI Act applies to processing data captured on record by a responsible party (1) domiciled in South Africa or (2) making use of means located in South Africa. The scope is similar to that of the EU Directive’s applicable rules, as the POPI Act applies to data processing;
- Firstly by or on behalf of a South African based ‘organisers’, for instance: by data processors for South African companies or
- Secondly, when an organisation uses services and infrastructure means for data processing located in South Africa.
EU Regulation 2016/679 Article 50 (Conflict) contrasts with the regulation’s antecedent, the EU Directive 95/46 (1995). Nevertheless, there is a particular provision in circumstances of conflict with supplementary laws.
The POPI Act operates to the exclusion of any other data protection rules or laws that are applicable. Unless such regulations or law provides for circumstances for the lawful handling of personal data that are more common than those set out in the POPI Act’s conditions for the authorised processing, the wide-ranging conditions prevail.
Many other countries provide data protection laws.[5] However, data users take the ultimate responsibility for and are accountable for the safekeeping and use of personal data under their control, even when they outsource the processing thereof to other parties.
The data users should take the appropriate measures to ensure that personal data is not processed for anything other than its initial specified purpose. Moreover, to keep it no longer than necessary and protect it against unauthorised or accidental access, processing erasure, loss, or use no matter whether they are processing the data themselves or have entrusted it to a third party to do so. Accordingly, they should fulfil their obligations under the law; data users must safeguard that adequate controls stand specified in their requirements and any agreements they negotiate with the outsourced data processors.
As previously illustrated, cloud services are considered a unique method of outsourced service. Data users will find the various business models somewhat different from the usual outsourced business models, except the private cloud, where cloud services stand dedicated to a single client and their requirements. Data users may be unable to exert the level of control they typically can in the one-on-one relationship with the traditional outsourcer. Data users may also be unaware of some cloud characteristics that potentially negatively impact personal data privacy, particularly when entrusting confidential data to a third party or cloud service provider for data processing or storage.
[1] A number of data protection laws define the data user and data controller as the bodies that gather, use and store such personal data belonging to the data subject or individuals.
[2] European Commission. (2012) Article 29 Data Protection Working Party. EC Europa.
[3] The Protection of Personal Information Act No. 4 of 2013 of South Africa, Policy, Law, Economics and Politics.
[4] Directive 95/46/EC of the European Parliament and the Council of 24 October 1995, on the protection of individuals with regard to the processing of personal data and on the free movement of such data. EC Europa.
[5] GREENLEAF, G. (2015) Global data privacy laws 2015: 109 countries, with European laws now a minority. Privacy Laws & Business International Report.
